CVE-2016-6312: Medium severity red hat enterprise linux vulnerability

Published Aug 4, 2016
·
Updated

A regression was found on RHEL-5.11 making apr-util and httpd vulnerable to billion laughs attack, also known as CVE-2009-1955, again.

Other sources

The moddontdothat component of the moddavsvn Apache module in Subversion as packaged in Red Hat Enterprise Linux 5.11 does not properly detect recursion during entity expansion, which allows remote authenticated users with access to the webdav repository to cause a denial of service (memory consumption and httpd crash). NOTE: Exists as a regression to CVE-2009-1955.

MITRE

Affected Software

1 affected component
redhat Enterprise Linux=5.11

Event History

Aug 4, 2016
Data Sourced
via Red Hat·02:03 PM
DescriptionSeverityAffected Software
Jul 14, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2016-6312?

CVE-2016-6312 is considered a medium severity vulnerability as it introduces a potential denial-of-service condition.

2

How do I fix CVE-2016-6312?

To fix CVE-2016-6312, you should upgrade to a patched version of RHEL or the affected Apache modules that address this vulnerability.

3

Which systems are affected by CVE-2016-6312?

CVE-2016-6312 specifically affects Red Hat Enterprise Linux version 5.11 that uses the apr-util and httpd components.

4

What type of attack does CVE-2016-6312 relate to?

CVE-2016-6312 is associated with the billion laughs attack, a form of denial-of-service attack that exploits XML processing.

5

Is CVE-2016-6312 a new vulnerability?

CVE-2016-6312 is a regression vulnerability that reopens previously addressed issues from CVE-2009-1955.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203